
Post List Featured Image Security & Risk Analysis
wordpress.org/plugins/post-list-featured-imageA plugin that adds the "Featured Image" column in admin posts and pages list.
Is Post List Featured Image Safe to Use in 2026?
Use With Caution
Score 63/100Post List Featured Image has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin "post-list-featured-image" v0.5.9 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating nonce and capability checks. The attack surface is relatively small, with no apparent vulnerabilities in REST API routes or cron events, and no dangerous functions identified in the code. However, a significant concern arises from the low percentage (14%) of properly escaped output. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied input could be injected into web pages without proper sanitization, potentially leading to malicious script execution.
The plugin's vulnerability history is also a cause for concern. It has a known CVE, which is currently unpatched, and it falls into the medium severity category. The common vulnerability type being Cross-Site Scripting further reinforces the risks identified in the static code analysis. The fact that the last vulnerability was in the future (2025-10-09) suggests this historical data might be simulated or indicative of a recurring issue. The lack of taint analysis results, while potentially indicating no critical flows were found, does not negate the clear risks identified in output escaping and historical vulnerabilities.
In conclusion, while the plugin employs some secure coding practices, the high prevalence of unescaped output and the presence of an unpatched medium-severity XSS vulnerability present a notable security risk. Developers should prioritize addressing the output escaping issues and promptly patching the known CVE to improve the plugin's overall security. The limited attack surface and use of prepared statements are strengths, but they are overshadowed by the evident XSS risk.
Key Concerns
- Currently unpatched CVE (medium severity)
- Low percentage of properly escaped output
- Historical XSS vulnerability pattern
Post List Featured Image Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Post List Featured Image <= 0.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Post List Featured Image Code Analysis
Output Escaping
Post List Featured Image Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Post List Featured Image Maintenance & Trust
Maintenance Signals
Community Trust
Post List Featured Image Alternatives
Featured Image Column Display
featured-image-column-display
A plugin that adds the "Featured Image" column in admin posts and pages list.
Everything Accordion
everything-accordion
The Everything Accordion is a simple widget that shows wordpress widgets, posts and pages in an pretty accordion.
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Preload Featured Images
preload-featured-images
Preload Featured Images automatically in posts to increase the PageSpeed Score.
Bulk Images to Posts
bulk-images-to-posts
Bulk upload images to automatically create posts / custom posts with featured images.
Post List Featured Image Developer Profile
1 plugin · 1K total installs
How We Detect Post List Featured Image
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-list-featured-image/assets/css/flexbox-grid.css/wp-content/plugins/post-list-featured-image/assets/css/settings-page.css/wp-content/plugins/post-list-featured-image/assets/js/settings-page.js/wp-content/plugins/post-list-featured-image/assets/js/settings-page.jsHTML / DOM Fingerprints
<!-- Plugin Settings Page --><!-- WHAT Settings Section --><!-- Plugin Settings Page --><!-- End Plugin Settings Page -->+8 moredata-plfi-tab="general"data-plfi-tab="list-table"data-plfi-tab="advanced"data-plfi-tab="license"plfi